Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

201–210 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#201
post #171
post #98

Earlier quoted context omitted.

I'm also interested in the postmortem to explain the processes that failed to allow the certificate to expire, but let's not overdramatize the situation by nitpicking about filling in form fields on bugzilla. The fact that the tree was closed is equivalent to DEFCON-1, which is all the priority anyone needs to understand the severity of this bug.

> which is all the priority anyone needs to understand the severity of this bug. Random user: What the fuck is a tree and why is the priority of this not higher yet?

> Random user: What the fuck is a tree and why is the priority of this not higher yet?

Not to be too glib, but any random user who is technically literate enough to know where to seek out Firefox's issue tracker and how to find the issue in question, and who has such a thorough understanding of issue trackers that they understand that such a thing as a priority field exists, is also going to be savvy enough to read the very first comment, and will be well aware of what it means, and will, one hopes, be rational enough to understand that the flurry of activity indicated by the issue in question is more important than a passing field in the bugzilla database.

If anyone expects Mozilla to take power users seriously, then we need to focus our criticism on the things that aren't just imagined trivialites. It makes me frustrated that the people who irrationally fly off the handle at the slightest perceived provocation are also the ones who implicitly encourage Mozilla to write off power users as more trouble than we're worth (and after ten years of watching these incessant whining non-comments on HN, I don't blame them anymore).

Re: Update Regarding Add-Ons in Firefox

#202

At the minimum they should add a testsuite that runs at least a month into the future to catch these kinds of things. There was a similar issue[0] a few years ago that was only caught a month in advance. Even better would be to set things up to only do a verify on install instead on every startup. [0] https://bugzilla.mozilla.org/show_bug.cgi?id=1267318

> Even better would be to set things up to only do a verify on install instead on every startup.

That would defeat the purpose of verification: "Add-on signing in Firefox helps protect against browser hijackers and other malware by making it harder for them to be installed." [1]

And it's not just malware that was doing that. Microsoft force-installed the ".NET Framework Assistant" into Firefox on Windows, and you had to edit the registry to remove it. [2] If I recall correctly, AVG and Logitech were also among the list of offenders.

[1] https://support.mozilla.org/en-US/kb/add-on-signing-in-firef... [2] https://support.microsoft.com/en-us/help/963707/how-to-remov...

Re: Update Regarding Add-Ons in Firefox

#203
post #184

Earlier quoted context omitted.

So you think Mozilla is enjoying this right now? And that this is going to help the perception and market share of Firefox? Hypothetically, lets say they took the opposite approach, and only checked the certificate date on installation. What would have happened? There would have been a brief period of time where people couldn't install extensions, it would have been fixed in a few hours, and this story would probably…

You are putting words in my mouth, please stop that. Instead of disabling this historically working feature which normally works great against hostile attacks such as MITM and malware this problem would've been avoided by a simple cron script which runs daily, and checks for expired certificates used within the infrastructure (both interaly used and externally used). The main competitor you mention, Google Chrome, is…

I'm not putting words in your mouth, you literally said this is a "Good Thing (tm)", because of hypothetical security reasons. Whereas I'm literally saying that this actually broke real privacy extensions, broke peoples software, and badly damaged their reputation.

As to your argument about security: doing the check on install instead of all the time, as I suggest is preferable, still protects against MITM and malware. The only argument for expiring software based on a calendar is that it might be a security risk if it's out of date. But first off, that is highly dependent on what the extension actually does. Also clearly we can see it's also a security risk to turn off privacy extensions without warning based on an arbitrary signing certificate.

Re: Update Regarding Add-Ons in Firefox

#206
post #166

Earlier quoted context omitted.

>This was treated as a five-alarm fire. I don't think it bothers me personally but it's funny you said that. Presumably you mean a "'no-alarm fire' because who has time to set off an alarm when there's a fire to fight"?!

> One-alarm, two-alarm, three-alarm fires, etc., are categories of fires indicating the level of response by local authorities. The term multiple-alarm is a quick way of indicating that a fire is severe and is difficult to contain. https://en.wikipedia.org/wiki/Multiple-alarm_fire The 5th level or a five-alarm fire, is the top level where you're basically talking all hands on deck.

In the UK they actually sound/flash alarms at locations and in the fire-station, do they not do that in USA? They do in the movies.

Still seems like an ironic choice, applies equally to the people saying it was DEFCON1. I'm pretty sure the military actually have displays indicating the status, but again that's based mainly on movies.

Re: Update Regarding Add-Ons in Firefox

#207
post #192

Earlier quoted context omitted.

checking revocations lists != certificate expiry

Revocation lists are often tied to certificate expiry, purging entries that are no longer valid due to expiry.

No, revocation lists are orthogonal, often used to invalidate a certificate before it expires.

Re: Update Regarding Add-Ons in Firefox

#208

Earlier quoted context omitted.

Yes, we are all quite advanced enough to footgun ourselves with abandon :) For everyone else, the fix is magically healing their browser without any intervention at all, and some of my high-skilled tech friends haven’t even noticed yet because they’re weekending and this all resolved itself before they realized it. Never underestimate the burden that being an “expert” places on your future time spend.

That hadn't occurred to me, but the fact that this is occurring on a weekend probably mitigates the impact to organizations that operate Monday-through-Friday. Sucks for the Mozillans who are scrambling right now though. Hope they get a long weekend to compensate.

[deleted]

Re: Update Regarding Add-Ons in Firefox

#209

Earlier quoted context omitted.

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

It is too late to listen to reason. Many commenters have spent their Saturday morning pushing a narrative that appeals to emotion.

I just switched my browser. Bye bye Firefox.

Re: Update Regarding Add-Ons in Firefox

#210

Earlier quoted context omitted.

> Also why it took 6 hrs to assign P1 to the bug Because people were staying up until the wee hours of the morning working on fixing it instead of toggling priorities in Bugzilla. This was treated as a five-alarm fire.

I agree with you, it was more important to do the work than to signal. However, I bet it’s likely they have procedures and policies for work that first involve signaling like for example the priority level. I’d be willing to bet lots of things surrounding this issue weren’t handled in a by the book manner. So if you are always going to wing it, why have a book (or a public priority level system) at all?

First, because priority is for things like major feature work, so that engineers can find the bugs that are useful to work on. In this case, everyone in the team responsible was already spending 100% of their time addressing the issue.

Second, because we care about solving problems, not being bureaucrats.

Post reply on HN